VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2023-46840MedMar 20, 2024
    risk 0.27cvss 4.1epss 0.00

    Incorrect placement of a preprocessor directive in source code results in logic that doesn't operate as intended when support for HVM guests is compiled out of Xen.

  • CVE-2024-25979MedFeb 19, 2024
    risk 0.27cvss 5.3epss 0.01

    The URL parameters accepted by forum search were not limited to the allowed parameters.

  • CVE-2023-32732MedJun 9, 2023
    risk 0.27cvss 5.3epss 0.01

    gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for `-bin` suffixed headers will result in a disconnection by the gRPC server, but is typically allowed by HTTP2 proxies. We…

  • CVE-2023-31130MedMay 25, 2023
    risk 0.27cvss 4.1epss 0.00

    c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function internally for configuration purposes which would require…

  • CVE-2021-3802MedNov 29, 2021
    risk 0.27cvss 4.2epss 0.01

    A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability.

  • CVE-2021-2374MedJul 21, 2021
    risk 0.27cvss 4.1epss 0.00

    Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.25 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise…

  • CVE-2021-2010MedJan 20, 2021
    risk 0.27cvss 4.2epss 0.01

    Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.50 and prior, 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple…

  • CVE-2020-15257MedDec 1, 2020
    risk 0.27cvss 5.2epss 0.03

    containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd before versions 1.3.9 and 1.4.3, the containerd-shim API is improperly exposed to host network containers. Access controls for the shim’s API socket verified…

  • CVE-2020-13882MedJun 18, 2020
    risk 0.27cvss 4.2epss 0.00

    CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition. The routine to check the log and report file permissions was not working as intended and could be bypassed locally. Because of the race, an unprivileged attacker can set up a log and…

  • CVE-2019-16232MedSep 11, 2019
    risk 0.27cvss 4.1epss 0.01

    drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.

  • CVE-2015-1839MedApr 13, 2017
    risk 0.27cvss 5.3epss 0.00

    modules/chef.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.

  • CVE-2015-1838MedApr 13, 2017
    risk 0.27cvss 5.3epss 0.00

    modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.

  • CVE-2024-0690MedFeb 6, 2024
    risk 0.26cvss 5.0epss 0.00

    An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive…

  • CVE-2023-39197MedJan 23, 2024
    risk 0.26cvss 4.0epss 0.01

    An out-of-bounds read vulnerability was found in Netfilter Connection Tracking (conntrack) in the Linux kernel. This flaw allows a remote user to disclose sensitive information via the DCCP protocol.

  • CVE-2022-3500MedNov 22, 2022
    risk 0.26cvss 5.1epss 0.00

    A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that stopped attestation attempts for that host leaving it in…

  • CVE-2021-32760MedJul 19, 2021
    risk 0.26cvss 5.0epss 0.02

    containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file…

  • CVE-2021-22212MedJun 8, 2021
    risk 0.26cvss 4.0epss 0.01

    ntpkeygen can generate keys that ntpd fails to parse. NTPsec 1.2.0 allows ntpkeygen to generate keys with '#' characters. ntpd then either pads, shortens the key, or fails to load these keys entirely, depending on the key type and the placement of the '#'. This results in the…

  • CVE-2021-3448MedApr 8, 2021
    risk 0.26cvss 4.0epss 0.02

    A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for a given network interface, dnsmasq uses a fixed port while forwarding queries. An attacker on the network, able to find the outgoing port used by dnsmasq, only needs to guess the…

  • CVE-2021-28543MedMar 16, 2021
    risk 0.26cvss 4.0epss 0.01

    Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not affect organizations that only install the Varnish Cache product; however, it is common to install both Varnish Cache and…

  • CVE-2020-1753MedMar 16, 2020
    risk 0.26cvss 5.0epss 0.01

    A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2.9.x versions prior to 2.9.7, when managing kubernetes using the k8s module. Sensitive parameters such as passwords and tokens are…

Page 200 of 268